{"id":9577,"date":"2022-05-23T13:51:38","date_gmt":"2022-05-23T01:51:38","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=9577"},"modified":"2022-05-23T13:51:38","modified_gmt":"2022-05-23T01:51:38","slug":"beware-when-anti-money-laundering-aml-creates-a-risk","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=9577","title":{"rendered":"Beware \u2013 When Anti-Money Laundering (AML) CREATES a risk"},"content":{"rendered":"\n\n\n[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<h3>That\u2019s right. AML is not only frustrating to many of us, but it has also created cyber-risks.<\/h3>\n<h3>The irony isn\u2019t lost on us.<\/h3>\n<p>We\u2019re honoured to support a large number of NZ law firms as clients, and it is a responsibility we take very seriously.<\/p>\n<h2>Law firms handle such a mix of highly confidential data that they are a particular target for ransomware attacks.<\/h2>\n<p>In this case, one of the firms needed a photo of a driver\u2019s license from one of their clients. Understandably, the client simply took a photo and emailed it back. Imagine their surprise when, just two days later, they discover a new \u2018AfterPay\u2019 account set up in their name, created using their driver\u2019s license information. A careful review of the law firm\u2019s logs and security settings determined that the information wasn\u2019t leaked from there, and it is pretty clear it was their client that was compromised.<\/p>\n<p>That could have been their email, but more likely it was simply that their phone was automatically synchronising their photos to somewhere online &#8211; for example, it might be a third party photo library app service.\u00a0 For example, most of us sync our photos to Google, Apple or Microsoft and these are fairly secure, but then we grant third-party access to these for some reason, and that creates a weakness.<\/p>\n<p>Alternative risk vectors include malware on the phone, or a family sharing account that has been compromised somehow..<\/p>\n<p><span style=\"font-size: 14px;\">I think many of us have used photos of identity documents for all sorts of things, from Travel Declarations to banking.\u00a0 What we need to do is find a way to ensure our personal devices aren&#8217;t letting us down.<\/span><\/p>\n<p>Risks like this exist in every organisation. They won\u2019t be exactly the same, but every organisation still needs to stop and think about how people interact and where the vulnerabilities rest. This particular risk is easily resolved with specialised apps, or even creating a solution within Microsoft 365 and we\u2019ll be reaching out to help every law firm mitigate it. The challenge is there are always risks and we have to work together to eliminate them.<\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]\n\n\n","protected":false},"excerpt":{"rendered":"<p>That\u2019s right. AML is not only frustrating to many of us, but it has also created cyber-risks. The irony isn\u2019t lost on us. We\u2019re honoured to support a large number of NZ law firms as clients, and it is a responsibility we take very seriously. Law firms handle such a mix of highly confidential data [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":9578,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,9,5],"tags":[],"class_list":["post-9577","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-legal-firms","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/9577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9577"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/9577\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}